Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/feishu-pr-notification.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ permissions:
jobs:
notify:
name: Notify Feishu
uses: openpi-dev/automation/.github/workflows/openpi-feishu-pr-notification.yml@main
uses: openpi-dev/automation/.github/workflows/openpi-feishu-pr-notification.yml@ac8a4140e4ce458a2ed693c5ec9798946ccc0dda # main
secrets:
FEISHU_PR_BOT_WEBHOOK: ${{ secrets.FEISHU_PR_BOT_WEBHOOK }}
FEISHU_PR_BOT_SECRET: ${{ secrets.FEISHU_PR_BOT_SECRET }}
2 changes: 1 addition & 1 deletion .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,6 @@ permissions:
jobs:
release:
name: Release
uses: openpi-dev/automation/.github/workflows/openpi-release.yml@main
uses: openpi-dev/automation/.github/workflows/openpi-release.yml@ac8a4140e4ce458a2ed693c5ec9798946ccc0dda # main
with:
tag: ${{ github.event_name == 'workflow_dispatch' && inputs.tag || github.ref_name }}
2 changes: 1 addition & 1 deletion RELEASING.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# Releasing OpenPI to npm

OpenPI releases `@tt-a1i/openpi` through [the Release workflow](.github/workflows/release.yml). The repository workflow keeps the release triggers and OIDC permission while following the reusable implementation on the [`openpi-dev/automation`](https://github.com/openpi-dev/automation) `main` branch. Do not publish from a local checkout.
OpenPI releases `@tt-a1i/openpi` through [the Release workflow](.github/workflows/release.yml). The repository workflow keeps the release triggers and OIDC permission while calling the reusable implementation from [`openpi-dev/automation`](https://github.com/openpi-dev/automation), pinned to a full commit SHA from its `main` branch. Adopting a newer automation commit requires a reviewed OpenPI pull request that updates the SHA. Do not publish from a local checkout.

## One-time repository setup

Expand Down
2 changes: 1 addition & 1 deletion docs/contributing/feishu-pr-notifications.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# Feishu PR notifications

The Feishu group bot notification is triggered by `.github/workflows/feishu-pr-notification.yml`. The caller follows the reusable implementation on the [`openpi-dev/automation`](https://github.com/openpi-dev/automation) `main` branch.
The Feishu group bot notification is triggered by `.github/workflows/feishu-pr-notification.yml`. The caller uses the reusable implementation from [`openpi-dev/automation`](https://github.com/openpi-dev/automation), pinned to a full commit SHA from its `main` branch, so automation changes reach this privileged `pull_request_target` workflow only through a reviewed OpenPI pull request that updates the SHA.

To enable it:

Expand Down
11 changes: 9 additions & 2 deletions tests/github/automation-workflows.test.ts
Original file line number Diff line number Diff line change
Expand Up @@ -6,11 +6,18 @@ function workflow(name: string) {
return readFileSync(`.github/workflows/${name}.yml`, "utf8");
}

test("shared repository workflows follow the automation main branch", () => {
test("shared repository workflows pin the automation main branch to a reviewed commit", () => {
const workflows = [workflow("feishu-pr-notification"), workflow("release")];

for (const source of workflows) {
assert.match(source, /uses: openpi-dev\/automation\/.+@main/u);
assert.match(
source,
/uses: openpi-dev\/automation\/\S+@[0-9a-f]{40} # main$/mu,
);
assert.doesNotMatch(
source,
/openpi-dev\/automation\/\S+@(?![0-9a-f]{40}\b)/u,
);
assert.doesNotMatch(source, /^\s+(?:run|steps|runs-on):/mu);
}
});
Expand Down
Loading